340bemployed.org

Your Free Source for 340B News and Commentary

  • Home
  • About Us
  • Employers
  • Job Seekers
  • Advertise
  • 340B Health
Job Seeker
Employer
Help/FAQs
Home
Jobs
Your Profile
Resources
SIGN IN
Job Seekers Sign In    
New Job Seeker? Sign Up    
Overview    
Saved Jobs    
Job Alerts    
Profile    
Documents    
Applications    

Loading...

Job Seekers, Welcome to 340B Employed
  • Search
  • Browse
  • Explore
  • Your Job Alerts
  • Your Saved Jobs
    0
InfoSec GRC Specialist - Intermediate
AdventHealth
SAVE savedJobs
SAVE savedJobs

InfoSec GRC Specialist - Intermediate

AdventHealth

Gmail Email Print
Application
AdventHealth Greater Orlando Logo
The application opened in a new tab.
By using this feature you agree to our Terms and Conditions and Privacy Policy.
Details
Posted:
February 18, 2021
Location:
Altamonte Springs, Florida
Show Map
Salary:
Open
Discipline:
Operations

Description

InfoSec GRC Specialist - Intermediate

AdventHealth Information Technology

Location Address: Orlando, FL

 

Top Reasons To Work At AdventHealth Corporate

  • Great benefits
  • Immediate Health Insurance Coverage
  • Career growth and advancement potential
  • Award-winning IT Department

 

Work Hours/Shift:

Full-Time, Monday – Friday

 

You Will Be Responsible For:

  • Develop workflows and administer enterprise GRC solution
  • Integrate enterprise GRC with other IT systems including identity and access management, IT ticketing system, asset inventory and vulnerability management via a REST API
  • Consult with customer to gather and define requirements
  • Continually optimize and enhance workflows
  • Provide status updates and present on GRC solution related topics to other team members in a professional manner
  • Support security training and awareness program by providing GRC contents to the training teams
  • Engage and work with a variety of internal departments and external organizations, including but not limited to legal firms, law enforcement agencies, and all other levels of government
  • Participate in the routine administrative work of the Information Security Office (InfoSec)
Qualifications

KNOWLEDGE AND SKILLS REQUIRED:

  • Governance, Risk, and Compliance (GRC) software platform administration experience.
  • Experience building and customizing GRC workflows including, forms, surveys, approval workflows, dashboards, database administration to support business and risk management processes
  • General knowledge of Information Security frameworks and how to integrate the control requirements in a GRC platform
  • Strong competency using Microsoft Visual Studio
  • Knowledge of API’s (REST) and JSON files.
  • Solid programming skills in at least one high-level language (e.g., Python, Ruby)
  • Strong ability with database concepts and API implementation
  • Well-versed in secure software development lifecycle procedures and concepts
  • Well-versed in project management procedures and concepts
  • Have soft skills, such as multi-tasking, self-starter, prioritization, time management, decision making, teamwork, presentation, communication and strong interpersonal skills
  • Advanced Knowledge of Microsoft suite of applications (Word, Excel, Visio, Project, etc.)

 

KNOWLEDGE AND SKILLS PREFERRED:

  • Navex Global’s IRM, Lockpath, software platform deployment and administration experience
  • Experience building and customizing Lockpath GRC workflows
  • Working knowledge of information security risk management and risk assessment methodologies.
  • Expert knowledge of one or more of the following: HITRUST, HIPAA Security and Privacy Rule, Red Flags Rule, Healthcare IT Standards (HITSP), HITECH, Meaningful Use (MU), COBIT, and PCI.
  • Strong background in business application, IT, and information security development
  • Expert knowledge of C#, SQL, and XML
  • Middleware experience with Demisto
  • A diverse set of technical skills, such as IT infrastructure, operating systems, data centers, access controls, cloud security, applications security, malware protection, security monitoring, physical security controls, etc.
  • Working knowledge of enterprise security systems (e.g., Firewalls, VPN, IDPS, SEIM), security threats and related risks, malware protection, virtual networks, asset management, pen-testing, vulnerability management, access management, configuration management, encryption techniques, cloud security, and 3rd party security

 

 

 

EDUCATION AND EXPERIENCE REQUIRED:

 

  • Bachelor’s degree in Computer Science or Information Systems or equivalent work experience.
  • 3-5 years of experience developing complex business and/or risk-based workflows in a professional services firm and/or large enterprise
  • 3 or more years of experience in information security

 

 

EDUCATION AND EXPERIENCE PREFERRED:

    • Master’s in computer science, information systems/technology, cybersecurity, or business administration from an accredited university
    • Experience in the healthcare industry doing information security
    • 2 or more years’ experience developing with a variety of API integrations

 

 

 

LICENSURE, CERTIFICATION OR REGISTRATION PREFERRED:

  • Cybersecurity certification
  • LockPath GRC Admin from Navex Global

 

Summary:

Governance, Risk and Compliance (GRC) Security Specialist - Intermediate is responsible for the development and administration of Information Technology Governance, Risk, and Compliance (GRC) solutions and content. This position will develop, integrate and administer complex enterprise GRC workflows, data, system integration and related tools. Other key activities include working with Information Security, Information Technology and business stakeholders to understand and support their use of the IT GRC platform and to ensure Information Security controls are managed though out a full lifecycle that includes policies, procedures, implementation, metrics, and assurance requirements. 

 

The GRC Security Specialist - Intermediate should also have the knowledge of industry best practices for Information Security GRC, industry recognized information security frameworks, proficiency in multiple development languages, database expertise, a robust knowledge of the security of information systems and techniques required to protect the confidentiality, integrity, and availability of sensitive information. Strong interpersonal and communication skills, critical thinking, analytical and problem-solving skills are required to avoid checkbox mentality and tackle unexpected challenges by coming up with intelligent ways of providing functionality and security. This role is focused on the GRC system and using a REST API service to integrate with other enterprise technology tools. The individual must have an excellent understanding of information security program needs, risks, along with project management experience. The individual should be able to work well under pressure, independently, and be able to perform effectively in a team setting to achieve organizational goals.


This facility is an equal opportunity employer and complies with federal, state and local anti-discrimination laws, regulations and ordinances.

Internal Number: 21003220
About AdventHealth
AdventHealth Greater Orlando (formerly Florida Hospital) is one of the largest faith-based health care providers in the United States. For 150 years, we have carried on a tradition of providing whole-person care that not only addresses patients' physical ailments, but also supports their emotional and spiritual well-being. We demonstrate the same level of compassion and care for our employees as well, doing all that we can to help them realize their full potential – both personally and professionally.
More Jobs from This Employer
BACK TO TOP
Help is on the way!
We're sorry you are having trouble applying for this job.

Please try loading this job using the following link before submitting your help request:

Error

Powered By Naylor Association Solutions




RSS 340B Informed

Privacy Policy | Terms of use

Copyright © 2019 · 340B Health